Several unauthorised SSL certificates have been found in the wild issuedfor the DigiNotar Certificate Authority, obtained through a security compromise with said company. Debian, like other softwaredistributors, has as a precaution decided to disable the DigiNotarRoot CA by default in the NSS crypto libraries.

For the oldstable distribution (lenny), this problem has been fixed inversion 3.12.3.1-0lenny5.

For the stable distribution (squeeze), this problem has been fixed inversion 3.12.8-1+squeeze2.

For the unstable distribution (sid), this problem has been fixed inversion 3.12.11-2.

We recommend that you upgrade your nss packages.

Further information about Debian Security Advisories, how to applythese updates to your system and frequently asked questions can befound at: http://www.debian.org/security/